find命令使用
二:find命令基础
find是Linux命令中最强大的文件查找工具。与locate不同,lacate是基于数据快速查找,而find直接在磁盘上实时搜索,支持按名称、类型、大小、时间、权限等多种条件组合查找的。
locate与find对比:
- locate:
locate是通过数据库进行搜索文件的,查找文件时需要更新数据库。
查找新创建的文件:
1)创建文件:
root@studry:~/wmn# touch wmn1234.txt
2)查找文件:
root@studry:~/wmn# locate wmn1234.txt
root@studry:~/wmn# #找不出文件,因为没有更新到数据库中。
更新数据库:
root@studry:~/wmn# updatedb
root@studry:~/wmn#
进行查找文件:
root@studry:~/wmn# locate wmn1234.txt
/root/wmn/wmn1234.txt
- find
find是通过磁盘上实时数据进行搜索查找文件的。
1)创建新文件:
root@studry:~/wmn# touch wmn456.txt
2)查找文件
root@studry:~/wmn# find . -name "wmn456.txt"
./wmn456.txt
2.1 查找方式:
2.1.1 按照文件名进行查找(-name/-iname)
2.1.1.1 -name(按照文件名)
环境准备:
root@studry:~# dnf install nginx -y
root@studry:~# systemctl start nginx
- 例子:
查找精确名称的文件:
root@studry:~# find /etc -name "nginx.conf"
/etc/nginx/nginx.conf
查找所有.conf所有的文件:
root@studry:~# find /etc -type f -name '*.conf'
/etc/lvm/lvm.conf
/etc/lvm/lvmlocal.conf
/etc/nvme/discovery.conf
/etc/resolv.conf
/etc/dnf/protected.d/setup.conf
/etc/dnf/protected.d/systemd.conf
查找以nginx开头的文件:
root@studry:~# find /etc -type f -name "nginx*"
/etc/logrotate.d/nginx
/etc/nginx/nginx.conf
/etc/nginx/nginx.conf.default
查找以.log结尾的文件:
root@studry:~# find /var/ -type f -name "*.log"
/var/log/audit/audit.log
/var/log/sssd/sssd_kcm.log
/var/log/tuned/tuned.log
/var/log/tuned/tuned-ppd.log
查找包含error的文件:
root@studry:~# find /var/log -name "*error*"
/var/log/nginx/error.log
2.1.1.2 -iname(按照文件名查找进行查找,不区分文件名大小写)
- 例子:不区分文件大小写查找文件:
root@studry:~# find /var/log -iname "*.LOG"
/var/log/audit/audit.log
/var/log/sssd/sssd_kcm.log
/var/log/tuned/tuned.log
/var/log/tuned/tuned-ppd.log
/var/log/anaconda/anaconda.log
2.1.2 -type按照文件类型
| 类型 | 含义 |
|---|---|
| f | 文件 |
| d | 目录 |
| l | 链接文件 |
| b | 块设备文件 |
| c | 字符设备文件 |
- 例子:
查找所有目录:
root@studry:~# find /etc -type d
查找所有文件不包括目录:
root@studry:~# find /etc -type f
查找所有配置文件:
root@studry:~# find /etc -type l
查找所有配置文件:
root@studry:~# find /etc -type f -name "*.conf"
/etc/lvm/lvm.conf
/etc/lvm/lvmlocal.conf
/etc/nvme/discovery.conf
查找所有子目录(--maxdepth是查找限制深度,1是显示一级目录)
root@studry:~# find /etc -maxdepth 1 -type d
/etc
/etc/lvm
/etc/nvme
/etc/dnf
/etc/fonts
/etc/skel
/etc/X11
/etc/hp
/etc/pki
/etc/issue.d
/etc/groff
2.1.3 按照文件大小查找(-size)
| 符号 | 含义 | 示例 |
|---|---|---|
| + | 大于 | +100M大于100M |
| - | 小于 | -100M小于100M |
- 例子:
查找大于100MB的文件:
root@studry:~# find / -type f -size +100M
查找小于10KB的文件:
root@studry:~# find / -type f -size -10k
查找大于10MB且小于50M的文件:
root@studry:~# find / -type f -size +10M -size -50M
/boot/vmlinuz-6.12.0-211.16.1.el10_2.0.1.x86_64
/boot/vmlinuz-0-rescue-e5e4a7dfe2e442df911f31353b7cb563
查找大于100Mb的文件,并显示大小:
root@studry:~# find / -type f -size +100M -exec ls -lh {} \;
-rw-------. 1 root root 234M 9月10日 14:34 /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img
-r--------. 1 root root 128T 9月11日 10:41 /proc/kcore
2.1.4 按照时间进行查找:
| 参数 | 说明 |
|---|---|
| -mtime | 按照修改时间进行查找,默认单位天 |
| -ctime | 按照修改文件属性时间进行查找,默认单位天 |
| -atime | 按照文件被读取的时间进行查找,默认单位天 |
| -mmin | 按照修改时间进行查找,默认单位分钟 |
| -cmin | 按照修改文件属性时间进行查找,默认单位分钟 |
| -amin | 按照文件被读取的时间进行查找,默认单位分钟 |
时间比较:
| 符号 | 含义 | 实例 |
|---|---|---|
| + | 大于(超过) | +7: 超过7天 |
| - | 小于(以内) | -7: 7天以内 |
| 无 | 等于(正好) | 7 :正好7天前 |
- 例子:
查找7天内修改的文件:
root@studry:~# find /var/log -type f -mtime -7
查找7天前修改的文件:
root@studry:~# find /var/log -mtime +7 -type
查找正好7天前修改的文件:
root@studry:~# find /var/log -mtime 7 -type f
root@studry:~#
查找30分钟内修改的文件:
root@studry:~# find /var/log -type f -mmin -30
/var/log/messages
/var/log/audit/audit.log
/var/log/cron
查找超过1天未访问的文件:
root@studry:~# find /var/log -type f -atime +1
查找1小时内修改的配置文件:
root@studry:~# find /etc -type f -mmin 60 -name "*.conf"
2.1.5 -perm-按权限查找
| 命令 | 说明 |
|---|---|
| find . -perm 644 | 精确匹配,文件u和g和o精确匹配644权限 |
| find . -perm -644 | 包含匹配,文件权限包含644,比如655或666等 |
| find . -perm /644 | 任意匹配,文件全ugo任意一个权限匹配某一位 |
- 例子
精确查找权限是644的文件:
root@studry:~# find /etc -type f -perm 644
查找所有777权限的文件:
root@studry:~# find / -type f -perm 777
/home/wmn/dir03/file03.txt
find: ‘/proc/3656/task/3656/fdinfo/6’: 没有那个文件或目录
find: ‘/proc/3656/fdinfo/5’: 没有那个文件或目录
find: ‘/run/user/42/doc’: 权限不够
查找至少包含指定权限的文件:
root@studry:~# find /etc -type f -perm -644
root@studry:~# find /etc -type f -perm /644
查找所有可执行文件:
root@studry:~# find /usr/bin -type f -perm /111
查找所有其他用户可写的文件(安全风险)
root@studry:~# find / -type f -perm -002
2.2 执行操作
2.2.1 常用的操作
| 操作 | 含义 |
|---|---|
| 打印(默认的操作) | |
| -ls | 类似于ls -l |
| -delete | 删除文件 |
| -exec | 执行命令操作 |
| -ok | 交互式执行 |
2.2.2 -exec用法
-exec是执行命令的操作。
语法: -exec 命令 {} ;
- {}:前边查询出来的文件
- ; 表示命令结束。
例子:
环境准备:
root@studry:~# mkdir wmn
root@studry:~# touch wmn/file{1..10}
root@studry:~# touch wmn/file{1..10}.txt
查找文件并且删除:
1)查找出来的文件:
root@studry:~# find . -type f -name "*.txt" -exec ls -l {} \;
-rw-------. 1 jinghui qa 0 9月10日 21:35 ./file1.txt
-rw-r-----. 1 root root 0 9月10日 21:46 ./file2.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file1.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file2.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file3.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file4.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file5.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file6.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file7.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file8.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file9.txt
-rw-r--r--. 1 root root 0 9月11日 10:49 ./wmn/file10.txt
-rw-r--r--. 1 root root 0 9月11日 10:53 ./wmn/wmn1234.txt
-rw-r--r--. 1 root root 0 9月11日 10:57 ./wmn/wmn456.txt
2)进行删除:
root@studry:~# find . -type f -name "*.txt" -exec rm -rf {} \;
root@studry:~# find . -type f -name "*.txt" -exec ls -l {} \;
查找并且复制:
1)创建备份目录:
root@studry:~# mkdir -p backup/config
2)进行复制:
root@studry:~# find /etc -type f -name "*.conf" -exec cp {} backup/config/ \;
3)查看是否复制成功
root@studry:~# ls backup/config/
000-shortnames.conf dracut.conf lvfs.conf s9036.conf
查找大文件并且显示出来:
root@studry:~# find / type f -size +100M -exec ls -lh {} \;
-rw-------. 1 root root 234M 9月10日 14:34 /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img
-r--------. 1 root root 128T 9月11日 14:11 /proc/kcore
2.2.3 -ok安全执行
-ok安全执行是会在执行前询问确认
root@studry:~/dir01# find . -type f -name "file*" -ok rm {} \;
< rm ... ./file1 > ? y
< rm ... ./file2 > ? n
< rm ... ./file3 > ? y
< rm ... ./file4 > ? y
< rm ... ./file5 > ? y
< rm ... ./file6 > ? y
< rm ... ./file7 > ? y
< rm ... ./file8 > ? y
< rm ... ./file9 > ? y
< rm ... ./file10 > ? y
root@studry:~/dir01# ls
file2
安全删除大文件:
root@studry:~/dir01# find / -type f -size +100M -ok rm -rf {} \;
< rm ... /boot/initramfs-0-rescue-e5e4a7dfe2e442df911f31353b7cb563.img > ? ^C
2.3 find与xargs结合
xargs作用是把一堆文件名凑在一起,一次上传给命令,少启动进程,它的处理速度比-exec速度要快,它更重要的作用是充当桥梁,把管道前边命令执行的结果,传输到管道另一边命令最后边,让很多命令不支持从管道读取数据,读取数据。
- 常用选项
| 选项 | 含义 | 示例 |
|---|---|---|
| -I | 替换字符串,使用占位符,把管道前边的命令执行结果传输到占位符中 | xargs -I {} cp {} /tmp |
| -0 | 处理空字符分隔 | xargs -0 |
- find + xargs实战实例
案例一:基础用法删除文件:
1)环境准备
root@studry:~# mkdir -p dir02
root@studry:~# cd dir02/
root@studry:~/dir02# touch file{01..10}.txt
root@studry:~/dir02# ls
file01.txt file02.txt file03.txt file04.txt file05.txt file06.txt file07.txt file08.txt file09.txt file10.txt
2)先用ls -l预览要操作的文件(安全习惯)
root@studry:~# find dir02 -type f -name "file*.txt" |xargs ls -lh
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file01.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file02.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file03.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file04.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file05.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file06.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file07.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file08.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file09.txt
-rw-r--r--. 1 root root 0 9月11日 16:04 dir02/file10.txt
3)确认无误后进行删除:
root@studry:~# find dir02 -type f -name "file*.txt"|xargs -I {} rm {}
root@studry:~# find dir02 -type f -name "file*.txt"
案例二: 使用-I {}占位符进行替换-复制文件
1)准备环境:
root@studry:~# mkdir -p dir03
root@studry:~# touch dir03/file{01..10}.txt
root@studry:~# tree dir03/
dir03/
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt
1 directory, 10 files
2)使用占位符{}:
root@studry:~# find dir03 -type f -name "file*txt" |xargs -I {} cp -r {} backup/file
root@studry:~# tree backup/file/
backup/file/
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt
1 directory, 10 files
3)使用自定义占位符:
root@studry:~# find dir03 -type f -name "file*txt" |xargs -I wmn cp -r wmn backup/file02
root@studry:~# tree backup/file02
backup/file02
├── file01.txt
├── file02.txt
├── file03.txt
├── file04.txt
├── file05.txt
├── file06.txt
├── file07.txt
├── file08.txt
├── file09.txt
└── file10.txt
1 directory, 10 files
案例三: 使用-print0 + xargs -0安全处理特殊文件名
-print0 + xargs0适用于处理一些特殊文件名,比如说处理文件名带有空格的。
1)环境准备:
root@studry:~# mkdir dir04
root@studry:~# touch dir04/file{00..10}.txt
root@studry:~# touch dir04/"file wmn.txt" #创建了带有空格文件名
root@studry:~# ls -lh dir04/
总计 0
-rw-r--r--. 1 root root 0 9月11日 16:17 file00.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file01.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file02.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file03.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file04.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file05.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file06.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file07.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file08.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file09.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 file10.txt
-rw-r--r--. 1 root root 0 9月11日 16:18 'file wmn.txt' #带有空格的文件名
2)常规操作:说明使用普通的,只要遇见空格就会回车。
root@studry:~# find dir04 -type f -name "file*txt" |xargs ls -lh
ls: 无法访问 'dir04/file': 没有那个文件或目录
ls: 无法访问 'wmn.txt': 没有那个文件或目录
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file00.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file01.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file02.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file03.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file04.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file05.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file06.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file07.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file08.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file09.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file10.txt
3)进行处理
方法一:
root@studry:~# find dir04 -type f -name "file*txt" |xargs -I {} ls -lh {}
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file00.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file01.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file02.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file03.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file04.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file05.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file06.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file07.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file08.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file09.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file10.txt
-rw-r--r--. 1 root root 0 9月11日 16:18 'dir04/file wmn.txt'
方法二:
root@studry:~# find dir04 -type f -name "file*txt" -print0 |xargs -0 ls -lh
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file00.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file01.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file02.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file03.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file04.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file05.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file06.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file07.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file08.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file09.txt
-rw-r--r--. 1 root root 0 9月11日 16:17 dir04/file10.txt
-rw-r--r--. 1 root root 0 9月11日 16:18 'dir04/file wmn.txt'
4)说明:
-print0 :用空字符'\0'分隔文件名,而非默认的换行符
-xargs -0:按空字符解析输入。
posted on 2026-09-12 17:15 wangmengnan 阅读(18) 评论(0) 收藏 举报
浙公网安备 33010602011771号