CLI AI

Delete files older than 30 days in Linux, safely

2026-05-01

The short answer is find /var/log/app -type f -mtime +30 -delete. The longer answer is that you should run it once without -delete, because the version of this command that goes wrong takes the whole directory with it. Here is the safe order, described the way you'd say it out loud.

1. Show me what would go first

clai
$ clai show files in /var/log/app older than 30 days, don't delete anything→ find /var/log/app -type f -mtime +30 -printf '%TY-%Tm-%Td  %p\n'2026-06-01  /var/log/app/app-june.log2026-07-10  /var/log/app/app-july.log

find without an action just prints. Read the list before you trust it — this is the step people skip.

2. How much space would that actually free?

clai
$ clai how much disk space would those old files free→ find /var/log/app -type f -mtime +30 -printf '%s\n' | awk '{s+=$1} END {printf "%.1f KB in %d files\n", s/1024, NR}'6.0 KB in 2 files

If the answer is a few kilobytes, the cleanup isn't your disk problem and you can stop here.

3. Now delete them

clai
$ clai delete those files older than 30 days→ find /var/log/app -type f -mtime +30 -delete

-delete prints nothing on success. That silence is normal.

4. Only .log files, only the top level

clai
$ clai delete only .log files older than 30 days in /var/log/app, don't go into subfolders→ find /var/log/app -maxdepth 1 -type f -name '*.log' -mtime +30 -delete

-maxdepth 1 is what keeps a cleanup job from wandering into a mounted volume.

5. By calendar date instead of "N days ago"

clai
$ clai find files last modified before July 1st 2026→ find /var/log/app -type f ! -newermt '2026-07-01' -printf '%TY-%Tm-%Td  %p\n'2026-05-01  /var/log/app/old.txt2026-06-01  /var/log/app/app-june.log

Useful when the cutoff is a release date, not a rolling window.

6. Clean up the empty directories left behind

clai
$ clai remove the empty folders left under /var/log/app→ find /var/log/app -mindepth 1 -type d -empty -delete

-mindepth 1 stops find from deleting the directory you pointed it at.

Gotchas

  • -delete must come last. find evaluates the expression left to right, so find . -delete -mtime +30 deletes everything before it ever checks the age. This is the single most expensive typo in this article.
  • -mtime +30 means at least 31 days. find truncates to whole 24-hour periods and +30 is strictly greater than 30, so a file modified 30.5 days ago is not matched.
  • Don't reach for -atime. Most Linux systems mount with relatime, so access times are only updated once a day at best. Age by modification time (-mtime) or change time (-ctime) instead.

Related questions

Why did find -delete remove more than I expected? Almost always flag order — see the first gotcha. -delete also implies -depth, which changes how the tree is walked.

How do I run this nightly? Put the tested command in cron with absolute paths: 0 3 * * * find /var/log/app -type f -mtime +30 -delete. Test it by hand first — cron gives you a different environment and a much smaller audience for mistakes.

Does this work on macOS? Yes, BSD find supports -mtime, -delete and -maxdepth. -printf is GNU-only, so use -print on macOS.

See also

Not sure a command is safe? CliAI labels every generated command SAFE, CAUTION or DANGER before it runs, and destructive ones need a typed confirmation. Install it in one line.