find命令使用

二:find命令基础

find是Linux命令中最强大的文件查找工具。与locate不同,lacate是基于数据快速查找,而find直接在磁盘上实时搜索,支持按名称、类型、大小、时间、权限等多种条件组合查找的。

locate与find对比:

  • locate:

locate是通过数据库进行搜索文件的,查找文件时需要更新数据库。

查找新创建的文件:

1)创建文件:
root@studry:~/wmn# touch wmn1234.txt
2)查找文件:
root@studry:~/wmn# locate wmn1234.txt 
root@studry:~/wmn#  #找不出文件,因为没有更新到数据库中。
更新数据库:
root@studry:~/wmn# updatedb
root@studry:~/wmn# 
进行查找文件:
root@studry:~/wmn# locate wmn1234.txt 
/root/wmn/wmn1234.txt
  • find

find是通过磁盘上实时数据进行搜索查找文件的。

1)创建新文件:
root@studry:~/wmn# touch wmn456.txt
2)查找文件
root@studry:~/wmn# find . -name "wmn456.txt" 
./wmn456.txt

2.1 查找方式:

2.1.1 按照文件名进行查找(-name/-iname)

2.1.1.1 -name(按照文件名)

环境准备:

root@studry:~# dnf install nginx -y 
root@studry:~# systemctl start nginx 
  • 例子:

查找精确名称的文件:

root@studry:~# find /etc -name "nginx.conf"
/etc/nginx/nginx.conf

查找所有.conf所有的文件:

root@studry:~# find /etc -type f -name '*.conf'
/etc/lvm/lvm.conf
/etc/lvm/lvmlocal.conf
/etc/nvme/discovery.conf
/etc/resolv.conf
/etc/dnf/protected.d/setup.conf
/etc/dnf/protected.d/systemd.conf

查找以nginx开头的文件:

root@studry:~# find /etc -type f -name "nginx*"
/etc/logrotate.d/nginx
/etc/nginx/nginx.conf
/etc/nginx/nginx.conf.default

查找以.log结尾的文件:

root@studry:~# find /var/ -type f -name "*.log"
/var/log/audit/audit.log
/var/log/sssd/sssd_kcm.log
/var/log/tuned/tuned.log
/var/log/tuned/tuned-ppd.log

查找包含error的文件:

root@studry:~# find /var/log -name "*error*"
/var/log/nginx/error.log

2.1.1.2 -iname(按照文件名查找进行查找,不区分文件名大小写)

  • 例子:不区分文件大小写查找文件:
root@studry:~# find /var/log -iname "*.LOG"
/var/log/audit/audit.log
/var/log/sssd/sssd_kcm.log
/var/log/tuned/tuned.log
/var/log/tuned/tuned-ppd.log
/var/log/anaconda/anaconda.log

2.1.2 -type按照文件类型

类型 含义
f 文件
d 目录
l 链接文件
b 块设备文件
c 字符设备文件
  • 例子:

查找所有目录:

root@studry:~# find /etc -type d 

查找所有文件不包括目录:

root@studry:~# find /etc -type f

查找所有配置文件:

root@studry:~# find /etc -type l

查找所有配置文件:

root@studry:~# find /etc -type f -name "*.conf"
/etc/lvm/lvm.conf
/etc/lvm/lvmlocal.conf
/etc/nvme/discovery.conf

查找所有子目录(--maxdepth是查找限制深度,1是显示一级目录)

root@studry:~# find /etc -maxdepth 1  -type d 
/etc
/etc/lvm
/etc/nvme
/etc/dnf
/etc/fonts
/etc/skel
/etc/X11
/etc/hp
/etc/pki
/etc/issue.d
/etc/groff

2.1.3 按照文件大小查找(-size)

符号 含义 示例
+ 大于 +100M大于100M
- 小于 -100M小于100M
  • 例子:

查找大于100MB的文件:

root@studry:~# find / -type f -size +100M

查找小于10KB的文件:

root@studry:~# find / -type f -size -10k

查找大于10MB且小于50M的文件:

root@studry:~# find / -type f -size +10M -size -50M
/boot/vmlinuz-6.12.0-211.16.1.el10_2.0.1.x86_64
/boot/vmlinuz-0-rescue-e5e4a7dfe2e442df911f31353b7cb563

查找大于100Mb的文件,并显示大小:

root@studry:~# find / -type f -size +100M -exec ls -lh {} \;
-rw-------. 1 root root 234M  9月10日 14:34 /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img
-r--------. 1 root root 128T  9月11日 10:41 /proc/kcore

2.1.4 按照时间进行查找:

参数 说明
-mtime 按照修改时间进行查找,默认单位天
-ctime 按照修改文件属性时间进行查找,默认单位天
-atime 按照文件被读取的时间进行查找,默认单位天
-mmin 按照修改时间进行查找,默认单位分钟
-cmin 按照修改文件属性时间进行查找,默认单位分钟
-amin 按照文件被读取的时间进行查找,默认单位分钟

时间比较:

符号 含义 实例
+ 大于(超过) +7: 超过7天
- 小于(以内) -7: 7天以内
无 等于(正好) 7 :正好7天前
  • 例子:

查找7天内修改的文件:

root@studry:~# find /var/log -type f -mtime -7 

查找7天前修改的文件:

root@studry:~# find /var/log -mtime +7 -type 

查找正好7天前修改的文件:

root@studry:~# find /var/log -mtime 7 -type f 
root@studry:~#

查找30分钟内修改的文件:

root@studry:~# find /var/log -type f -mmin -30
/var/log/messages
/var/log/audit/audit.log
/var/log/cron

查找超过1天未访问的文件:

root@studry:~# find /var/log -type f  -atime +1

查找1小时内修改的配置文件:

root@studry:~# find /etc -type f -mmin 60 -name "*.conf"

2.1.5 -perm-按权限查找

命令 说明
find . -perm 644 精确匹配,文件u和g和o精确匹配644权限
find . -perm -644 包含匹配,文件权限包含644,比如655或666等
find . -perm /644 任意匹配,文件全ugo任意一个权限匹配某一位
  • 例子

精确查找权限是644的文件:

root@studry:~# find /etc -type f -perm 644

查找所有777权限的文件:

root@studry:~# find / -type f -perm 777
/home/wmn/dir03/file03.txt
find: ‘/proc/3656/task/3656/fdinfo/6’: 没有那个文件或目录
find: ‘/proc/3656/fdinfo/5’: 没有那个文件或目录
find: ‘/run/user/42/doc’: 权限不够

查找至少包含指定权限的文件:

root@studry:~# find /etc  -type f -perm -644 
root@studry:~# find /etc  -type f -perm /644 

查找所有可执行文件:

root@studry:~# find /usr/bin -type f -perm /111

查找所有其他用户可写的文件(安全风险)

root@studry:~# find / -type f -perm -002

2.2 执行操作

2.2.1 常用的操作

操作 含义
-print 打印(默认的操作)
-ls 类似于ls -l
-delete 删除文件
-exec 执行命令操作
-ok 交互式执行

2.2.2 -exec用法

-exec是执行命令的操作。

语法: -exec 命令 {} ;

  • {}:前边查询出来的文件
  • ; 表示命令结束。

例子:

环境准备:

root@studry:~# mkdir wmn
root@studry:~# touch wmn/file{1..10} 
root@studry:~# touch wmn/file{1..10}.txt

查找文件并且删除:

1)查找出来的文件:
root@studry:~# find . -type f -name "*.txt" -exec ls -l {} \;
-rw-------. 1 jinghui qa 0  9月10日 21:35 ./file1.txt
-rw-r-----. 1 root root 0  9月10日 21:46 ./file2.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file1.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file2.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file3.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file4.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file5.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file6.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file7.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file8.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file9.txt
-rw-r--r--. 1 root root 0  9月11日 10:49 ./wmn/file10.txt
-rw-r--r--. 1 root root 0  9月11日 10:53 ./wmn/wmn1234.txt
-rw-r--r--. 1 root root 0  9月11日 10:57 ./wmn/wmn456.txt
2)进行删除:
root@studry:~# find . -type f -name "*.txt" -exec rm -rf {} \;
root@studry:~# find . -type f -name "*.txt" -exec ls -l {} \;

查找并且复制:

1)创建备份目录:
root@studry:~# mkdir -p backup/config
2)进行复制:
root@studry:~# find /etc -type f -name "*.conf" -exec cp {} backup/config/ \;
3)查看是否复制成功
root@studry:~# ls backup/config/
000-shortnames.conf                      dracut.conf                  lvfs.conf                                        s9036.conf

查找大文件并且显示出来:

root@studry:~# find / type f -size +100M -exec ls -lh {} \;
-rw-------. 1 root root 234M  9月10日 14:34 /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img
-r--------. 1 root root 128T  9月11日 14:11 /proc/kcore

2.2.3 -ok安全执行

-ok安全执行是会在执行前询问确认

root@studry:~/dir01# find . -type f -name "file*" -ok rm {} \;
< rm ... ./file1 > ? y
< rm ... ./file2 > ? n
< rm ... ./file3 > ? y
< rm ... ./file4 > ? y
< rm ... ./file5 > ? y
< rm ... ./file6 > ? y
< rm ... ./file7 > ? y
< rm ... ./file8 > ? y
< rm ... ./file9 > ? y
< rm ... ./file10 > ? y
root@studry:~/dir01# ls 
file2

安全删除大文件:

root@studry:~/dir01# find / -type f -size +100M  -ok rm -rf {} \;
< rm ... /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img > ? ^C

2.3 find与xargs结合

xargs作用是把一堆文件名凑在一起,一次上传给命令,少启动进程,它的处理速度比-exec速度要快,它更重要的作用是充当桥梁,把管道前边命令执行的结果,传输到管道另一边命令最后边,让很多命令不支持从管道读取数据,读取数据。

  • 常用选项
选项 含义 示例
-I 替换字符串,使用占位符,把管道前边的命令执行结果传输到占位符中 xargs -I {} cp {} /tmp
-0 处理空字符分隔 xargs -0
  • find + xargs实战实例

案例一:基础用法删除文件:

1)环境准备
root@studry:~# mkdir -p dir02
root@studry:~# cd dir02/
root@studry:~/dir02# touch file{01..10}.txt
root@studry:~/dir02# ls
file01.txt  file02.txt  file03.txt  file04.txt  file05.txt  file06.txt  file07.txt  file08.txt  file09.txt  file10.txt
2)先用ls -l预览要操作的文件(安全习惯)
root@studry:~# find dir02 -type f -name "file*.txt" |xargs ls -lh
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file01.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file02.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file03.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file04.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file05.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file06.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file07.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file08.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file09.txt
-rw-r--r--. 1 root root 0  9月11日 16:04 dir02/file10.txt
3)确认无误后进行删除:
root@studry:~# find dir02 -type f -name "file*.txt"|xargs -I {} rm {}
root@studry:~# find dir02 -type f -name "file*.txt"

案例二: 使用-I {}占位符进行替换-复制文件

1)准备环境:
root@studry:~# mkdir -p dir03
root@studry:~# touch dir03/file{01..10}.txt
root@studry:~# tree dir03/
dir03/
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt

1 directory, 10 files
2)使用占位符{}:
root@studry:~# find dir03 -type f -name "file*txt" |xargs -I {} cp -r {} backup/file
root@studry:~# tree backup/file/
backup/file/
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt

1 directory, 10 files
3)使用自定义占位符:
root@studry:~# find dir03 -type f -name "file*txt" |xargs -I wmn cp -r wmn backup/file02
root@studry:~# tree backup/file02
backup/file02
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt

1 directory, 10 files

案例三: 使用-print0 + xargs -0安全处理特殊文件名

-print0 + xargs0适用于处理一些特殊文件名,比如说处理文件名带有空格的。
1)环境准备:
root@studry:~# mkdir  dir04
root@studry:~# touch dir04/file{00..10}.txt 
root@studry:~# touch dir04/"file wmn.txt"  #创建了带有空格文件名
root@studry:~# ls -lh dir04/
总计 0
-rw-r--r--. 1 root root 0  9月11日 16:17  file00.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file01.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file02.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file03.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file04.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file05.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file06.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file07.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file08.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file09.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  file10.txt
-rw-r--r--. 1 root root 0  9月11日 16:18 'file wmn.txt'  #带有空格的文件名
2)常规操作:说明使用普通的,只要遇见空格就会回车。
root@studry:~# find dir04 -type f -name "file*txt" |xargs ls -lh
ls: 无法访问 'dir04/file': 没有那个文件或目录
ls: 无法访问 'wmn.txt': 没有那个文件或目录
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file00.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file01.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file02.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file03.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file04.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file05.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file06.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file07.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file08.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file09.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file10.txt
3)进行处理
方法一:
root@studry:~# find dir04  -type f -name "file*txt" |xargs -I {} ls -lh {}
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file00.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file01.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file02.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file03.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file04.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file05.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file06.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file07.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file08.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file09.txt
-rw-r--r--. 1 root root 0  9月11日 16:17 dir04/file10.txt
-rw-r--r--. 1 root root 0  9月11日 16:18 'dir04/file wmn.txt'
方法二:
root@studry:~# find dir04 -type f -name "file*txt" -print0 |xargs -0 ls -lh 
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file00.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file01.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file02.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file03.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file04.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file05.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file06.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file07.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file08.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file09.txt
-rw-r--r--. 1 root root 0  9月11日 16:17  dir04/file10.txt
-rw-r--r--. 1 root root 0  9月11日 16:18 'dir04/file wmn.txt'
4)说明:
-print0 :用空字符'\0'分隔文件名,而非默认的换行符
-xargs -0:按空字符解析输入。

posted on 2026-09-12 17:15  wangmengnan  阅读(18)  评论(0)    收藏  举报

导航