The short answer is find /var/log/app -type f -mtime +30 -delete. The longer answer is that you should run it once without -delete, because the version of this command that goes wrong takes the whole directory with it. Here is the safe order, described the way you'd say it out loud.
1. Show me what would go first
$ clai show files in /var/log/app older than 30 days, don't delete anything→ find /var/log/app -type f -mtime +30 -printf '%TY-%Tm-%Td %p\n'2026-06-01 /var/log/app/app-june.log2026-07-10 /var/log/app/app-july.log
find without an action just prints. Read the list before you trust it — this is the step people skip.
2. How much space would that actually free?
$ clai how much disk space would those old files free→ find /var/log/app -type f -mtime +30 -printf '%s\n' | awk '{s+=$1} END {printf "%.1f KB in %d files\n", s/1024, NR}'6.0 KB in 2 files
If the answer is a few kilobytes, the cleanup isn't your disk problem and you can stop here.
3. Now delete them
$ clai delete those files older than 30 days→ find /var/log/app -type f -mtime +30 -delete
-delete prints nothing on success. That silence is normal.
4. Only .log files, only the top level
$ clai delete only .log files older than 30 days in /var/log/app, don't go into subfolders→ find /var/log/app -maxdepth 1 -type f -name '*.log' -mtime +30 -delete
-maxdepth 1 is what keeps a cleanup job from wandering into a mounted volume.
5. By calendar date instead of "N days ago"
$ clai find files last modified before July 1st 2026→ find /var/log/app -type f ! -newermt '2026-07-01' -printf '%TY-%Tm-%Td %p\n'2026-05-01 /var/log/app/old.txt2026-06-01 /var/log/app/app-june.log
Useful when the cutoff is a release date, not a rolling window.
6. Clean up the empty directories left behind
$ clai remove the empty folders left under /var/log/app→ find /var/log/app -mindepth 1 -type d -empty -delete
-mindepth 1 stops find from deleting the directory you pointed it at.
Gotchas
-deletemust come last.findevaluates the expression left to right, sofind . -delete -mtime +30deletes everything before it ever checks the age. This is the single most expensive typo in this article.-mtime +30means at least 31 days.findtruncates to whole 24-hour periods and+30is strictly greater than 30, so a file modified 30.5 days ago is not matched.- Don't reach for
-atime. Most Linux systems mount withrelatime, so access times are only updated once a day at best. Age by modification time (-mtime) or change time (-ctime) instead.
Related questions
Why did find -delete remove more than I expected? Almost always flag order — see the first gotcha. -delete also implies -depth, which changes how the tree is walked.
How do I run this nightly? Put the tested command in cron with absolute paths: 0 3 * * * find /var/log/app -type f -mtime +30 -delete. Test it by hand first — cron gives you a different environment and a much smaller audience for mistakes.
Does this work on macOS? Yes, BSD find supports -mtime, -delete and -maxdepth. -printf is GNU-only, so use -print on macOS.
See also
- Sweep old logs and backups with one sentence
- Stop memorizing find flags: ask for what you want
- Cron without the mind games: "every Monday at 3 AM" → working schedule
Not sure a command is safe? CliAI labels every generated command SAFE, CAUTION or DANGER before it runs, and destructive ones need a typed confirmation. Install it in one line.