# A better way to Query Log!

**URL:** https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033
**Category:** Implemented
**Created:** [October 31, 2019, 11:21pm UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033 "2019-10-31T23:21:49Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Sovdite](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/s/db5fbb/32.png) [@Sovdite](https://discourse.pi-hole.net/u/Sovdite)
#### Post date: [October 31, 2019, 11:21pm UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033/1 "2019-10-31T23:21:49Z")

</div>

Hello,

I work with all kinds of logging and alerts regularly in my profession, and one tool we often use is Splunk. I love Pi-hole but I think there's some room for improvement on the Query log section in it.

There should be a filter option in Query Logging, preferably for any of the columns there, and simultaneously filterable. People often need to narrow down on a specific set of criteria. For example, a range on the time column, a filtering status to blocked or OK (or even OK cached!), a specific client IP, or even a domain (maybe regex, maybe a word? Anything would help!).

Let's give a situation to think about: A laptop isn't loading something you think it should be. You head over to the Query Log... now how do we see JUST the blocked entries right now as pi-hole is today? We have to sort through all sorts of noise looking at IPs, times, domains, etc. If we could filter... how about the blocked entries in the last 15 minutes only? What about a 10 min window that happened an hour ago? How about the blocked entries, in the last 15 minutes, with the word "pi-hole" in it to narrow it down? 🙂 With filtering we could do all that. People could find what they were looking for quickly and easily.

Take the troubleshooting a step further: We could even then learn that traffic matching the criteria was all coming from a certain IP, remove the domain word filter, and filter down on that IP instead, and now they have a list of the blocked entries for a given time period, for a given IP and be able to much better sort out what passed and what was blocked, and if something needs to be white-listed.

In short, filtering! The columns need filtering please!

Thanks all,

---

<div class="post-metadata">

### Author: ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)
#### Post date: [October 31, 2019, 11:53pm UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033/2 "2019-10-31T23:53:57Z")

</div>

As a workaround until such a feature is implemented, you can do this from the command line with grep and the log at /var/log/pihole.log.

---

<div class="post-metadata">

### Author: ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)
#### Post date: [June 1, 2020, 7:21pm UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033/3 "2020-06-01T19:21:39Z")

</div>

> [@Sovdite](#):
>
> In short, filtering! The columns need filtering please!

Advanced (multiple) filtering in Query log is been worked on.

> [@Explicit Search in Pi-hole Admin Console](https://discourse.pi-hole.net/t/explicit-search-in-pi-hole-admin-console/28893):
>
> When using the Query Log Search field, I can't seem to search explicitly, even with quotation marks. For example I want to filter/search for IP 10.0.1.6, but instead I'm getting 10.0.1.6\*, where the \* is all other numbers as well. Is there a way to do this through the admin console or must I use the terminal? Thanks.

---

<div class="post-metadata">

### Author: ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)
#### Post date: [July 16, 2020, 8:37am UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033/4 "2020-07-16T08:37:25Z")

</div>

Advanced filtering is implemented in v5.1  
[https://pi-hole.net/2020/07/15/pi-hole-5-1-released/](https://pi-hole.net/2020/07/15/pi-hole-5-1-released/)

---

<div class="post-metadata">

### Author: ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)
#### Post date: [July 16, 2020, 8:37am UTC](https://discourse.pi-hole.net/t/a-better-way-to-query-log/25033/5 "2020-07-16T08:37:28Z")

</div>


