kmail.at
← learning

linux · difficulty ◆◆◆

find — locate files by criteria

Walk the filesystem and return only what matches your criteria.

`find` and `grep` are the two tools people swap on autopilot — then wonder why `grep -r` mangles their logs. find does not search text; it walks the filesystem. Get that straight and half the confusion disappears.

2026-08-12 · 7 min read

$ find

What it does

find walks a directory tree and prints (or acts on) files that match a set of tests: name, type, size, modification time, permissions, and more. It is the filesystem version of grep — instead of matching text lines, it matches files.

Why it matters

find answers "where is this file?" and "which files changed recently?" in one command. Unlike ls, it searches recursively by default and can execute actions on results with -exec, making it a scripting workhorse.

Example

$ find . -name '*.log'
./server.log
./build/server.log
./cache/debug.log

-name does a case-sensitive glob match on the filename.

$ find /var/log -type f -mtime -2
/var/log/syslog
/var/log/auth.log
/var/log/nginx/access.log

-mtime -2 finds files modified in the last 2 days.

Common flags

-name
match filename (case-sensitive glob)
-iname
match filename, ignoring case
-type
match type: f=file, d=dir, l=symlink
-size
match size, e.g. +1M (larger than 1 megabyte)
-mtime
match modification age in days (e.g. -2, +30)
-exec
run a command on each result, e.g. ... -exec rm {} ;

History

Origin

find has been part of Unix since the 1970s. Its unusual expression syntax (predicates that can be combined with -and, -or, and -not) was ahead of its time and remains largely unchanged today. It is a direct ancestor of more modern search tools.

Fun fact

Modern systems often add alternatives — the newer "fd" and "ripgrep" (rg) are faster on big trees — but find is guaranteed present on every Unix-like system, which is why scripts still rely on it.

Fun facts

Pros & cons

pros

  • + Universal and guaranteed present on every Unix-like system
  • + Recursive by default, with powerful boolean predicate expressions
  • + Can act on results (-exec) in addition to finding them
  • + Expressions cover name, type, size, time, permissions, and depth

cons

  • − Per-match -exec is slow on large trees
  • − Expression syntax is easy to get wrong without parentheses
  • − No built-in sorting or output formatting — pipe to sort or use -printf
  • − Modern alternatives like fd are faster and have saner defaults

Takeaways

  1. 1Quote patterns so the shell does not expand them first
  2. 2Combine tests with parentheses and -o to build precise searches
  3. 3Use -mtime -7 to find everything changed in the last week
  4. 4For bulk actions, pipe to xargs -0 instead of -exec
  5. 5Try fd (a faster find) once you outgrow the syntax

Related commands

← all learning