# Audit Log

**URL:** <https://discourse.pi-hole.net/t/audit-log/2058>\
**Category:** Implemented\
**Created:** [March 6, 2017, 1:27pm UTC](https://discourse.pi-hole.net/t/audit-log/2058 "2017-03-06T13:27:56Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [March 6, 2017, 1:27pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/1 "2017-03-06T13:27:56Z")

</div>

The idea is to create an Audit log page, that looks maybe something link this:

```plaintext
---------------------------------------------------------------------------------
| Permitted domains | Blocked domains |
|-----------------------------------|-------------------------------------------|
| google.de [Accept] [Blacklist] | googleadservices.com [Accept] [Whitelist] |
| ebay.com [Accept] [Blacklist] | somebadguy.com [Accept] [Whitelist] |
| amazon.co.uk [Accept] [Blacklist] | *.microsoft.com [Accept] [Whitelist] |
| ... | ... |
---------------------------------------------------------------------------------

```

The list will contain all lists that have been found in the Pi-hole log. Once, you click on `[Accept]`, it will be removed from this table and saved in some list, so that it wouldn't be shown in the future. However, it will also give you the option to `[White-/Blacklist]` this domain with one single click (and hide it afterwards as well, since you have decided what will happen with it).

---

<div class="post-metadata">

**Author:** ![PromoFaux](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/promofaux/32/1545_2.png) [@PromoFaux](https://discourse.pi-hole.net/u/PromoFaux)\
**Post date:** [March 6, 2017, 1:30pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/2 "2017-03-06T13:30:16Z")

</div>

#whendevssubmitfeaturerequests

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [March 6, 2017, 1:31pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/3 "2017-03-06T13:31:53Z")

</div>

Made it better visible. It is already hidden in [here](https://discourse.pi-hole.net/t/request-add-filter-whitelisted-checkbox-to-query-log/1661/19).

---

<div class="post-metadata">

**Author:** ![r0ckarong](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/r0ckarong/32/770_2.png) [@r0ckarong](https://discourse.pi-hole.net/u/r0ckarong)\
**Post date:** [March 6, 2017, 1:39pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/4 "2017-03-06T13:39:26Z")

</div>

Actually I'm the annoying sh\*t who keeps asking for this 😌

---

<div class="post-metadata">

**Author:** ![WaLLy3K](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/wally3k/32/649_2.png) [@WaLLy3K](https://discourse.pi-hole.net/u/WaLLy3K)\
**Post date:** [April 14, 2017, 9:48am UTC](https://discourse.pi-hole.net/t/audit-log/2058/5 "2017-04-14T09:48:39Z")

</div>

Having the ability to view hits per domain (sorted by highest to lowest, but reverse sorting would be a neat optional thing) is **hugely** useful, given I already use the "Top Domains" feature on the dashboard in this fashion!

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [April 21, 2017, 11:22pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/6 "2017-04-21T23:22:43Z")

</div>

The required changes have been implemented in the `FTL` engine and can be used by adding ` for audit` to the commands (e.g. via `telnet`). Like

```auto
>top-ads for audit

```

> [@WaLLy3K](#):
>
> reverse sorting would be a neat optional thing

I implemented this as well in the backend (add ` desc`, like in `>top-ads desc`), but let's see what changes are necessary in the PHP API. Next steps are the implementation in the web interface and the connected core changes to add new accepted files to the audit list file.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [April 22, 2017, 2:15pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/7 "2017-04-22T14:15:17Z")

</div>

See  
[https://github.com/pi-hole/AdminLTE/pull/479](https://github.com/pi-hole/AdminLTE/pull/479)  
and  
[https://github.com/pi-hole/pi-hole/pull/1399](https://github.com/pi-hole/pi-hole/pull/1399)

 ![](https://discourse.pi-hole.net/uploads/default/original/3X/6/9/691714f3f14179009d7ca3c736c6766a54d3cb96.png)

You can join testing the development version while still in progress via:

```auto
sudo pihole checkout web new/audit-log
sudo pihole checkout core new/auditlog

```

Note that you will need `FTL v2.6` for the audit log

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [April 22, 2017, 2:47pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/8 "2017-04-22T14:47:52Z")

</div>

@r0ckarong @WaLLy3K

I'm interested in your opinion. Currently, I don't feel like I should implement the descending order property. The web interface part is still marked as `[Work in progress]` to indicate that it has not been finished (maybe?).

The domains are stored in `/etc/pihole/auditlog.list` which is a file that is hard-coded in `FTL`.

---

<div class="post-metadata">

**Author:** ![r0ckarong](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/r0ckarong/32/770_2.png) [@r0ckarong](https://discourse.pi-hole.net/u/r0ckarong)\
**Post date:** [April 24, 2017, 12:02pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/9 "2017-04-24T12:02:13Z")

</div>

I have switched to the dev branch you mentioned above and have access to the WIP state.

To properly understand the "Audit" button adds this to "auditlog" and ignores this from future listing yes?

---

<div class="post-metadata">

**Author:** ![r0ckarong](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/r0ckarong/32/770_2.png) [@r0ckarong](https://discourse.pi-hole.net/u/r0ckarong)\
**Post date:** [April 24, 2017, 12:08pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/10 "2017-04-24T12:08:26Z")

</div>

Number of items in auditlog.list should be displayed in gravity output imho.

Otherwise this is really useful and pretty much what I though of initially. This makes filtering "new" domains that keep cropping up much easier to manage.

Can you add some functionality to the audit log page that registers when you have made changes to black/whitelist and prompts you to Update the lists? A fat button "Update lists" would be helpful too. It's somewhat unintuitive to make changes to abstract lists and then having to pull up what looks and feels like an update tool to write these changes.

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [April 24, 2017, 4:26pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/11 "2017-04-24T16:26:27Z")

</div>

> [@r0ckarong](#):
>
> To properly understand the "Audit" button adds this to "auditlog" and ignores this from future listing yes?

Yes

> [@r0ckarong](#):
>
> Number of items in auditlog.list should be displayed in gravity output imho.

Okay

> [@r0ckarong](#):
>
> Can you add some functionality to the audit log page that registers when you have made changes to black/whitelist and prompts you to Update the lists? A fat button "Update lists" would be helpful too. It's somewhat unintuitive to make changes to abstract lists and then having to pull up what looks and feels like an update tool to write these changes.

I see what you mean and will think about how to implement that best

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [June 27, 2017, 1:29pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/12 "2017-06-27T13:29:01Z")

</div>

Implemented. Will be included in the next release.

---

<div class="post-metadata">

**Author:** ![ripa](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/r/cc9497/32.png) [@ripa](https://discourse.pi-hole.net/u/ripa)\
**Post date:** [August 14, 2018, 7:05pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/13 "2018-08-14T19:05:42Z")

</div>

Hey, sry for this but I cant find the solution.  
I pressed the button "Audit" for 2 domains on the Audit Log Page. How can I undo this? Where can I find the domains I added to auditing? It looks like these domains arent blocked anymore.

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 14, 2018, 7:24pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/14 "2018-08-14T19:24:33Z")

</div>

The audit log entries are in `/etc/pihole/auditlog.list`

Edit that file to remove the erroneous entries, then restart pihole-FTL with `sudo service pihole-FTL restart`

---

<div class="post-metadata">

**Author:** ![Mcat12](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/mcat12/32/20_2.png) [@Mcat12](https://discourse.pi-hole.net/u/Mcat12)\
**Post date:** [March 23, 2019, 11:45pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/15 "2019-03-23T23:45:33Z")

</div>

A post was split to a new topic: [Can not access audit log](https://discourse.pi-hole.net/t/can-not-access-audit-log/18645)

---

<div class="post-metadata">

**Author:** ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)\
**Post date:** [October 17, 2020, 7:05pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/16 "2020-10-17T19:05:05Z")

</div>

A post was split to a new topic: [What does the audit log do](https://discourse.pi-hole.net/t/what-does-the-audit-log-do/39532)

---

<div class="post-metadata">

**Author:** ![HybridZach\_1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/h/9fc29f/32.png) [@HybridZach\_1](https://discourse.pi-hole.net/u/HybridZach_1)\
**Post date:** [May 13, 2025, 8:29pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/17 "2025-05-13T20:29:19Z")

</div>

Hi, has this feature been removed? Or am I blind. Where do I find this/achive the same result in the latest version?

---

<div class="post-metadata">

**Author:** ![rdwebdesign](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/rdwebdesign/32/51363_2.png) [@rdwebdesign](https://discourse.pi-hole.net/u/rdwebdesign)\
**Post date:** [May 13, 2025, 9:13pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/18 "2025-05-13T21:13:37Z")

</div>

> [@HybridZach\_1](#):
>
> has this feature been removed?

Yes.

---

<div class="post-metadata">

**Author:** ![HybridZach\_1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/h/9fc29f/32.png) [@HybridZach\_1](https://discourse.pi-hole.net/u/HybridZach_1)\
**Post date:** [May 13, 2025, 9:25pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/19 "2025-05-13T21:25:11Z")

</div>

Oh thats a shame, is there no way to achieve the same result currently? I need to remove a domain from showing up every like 5 seconds from the log but still block it.

---

<div class="post-metadata">

**Author:** ![rdwebdesign](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/rdwebdesign/32/51363_2.png) [@rdwebdesign](https://discourse.pi-hole.net/u/rdwebdesign)\
**Post date:** [May 13, 2025, 9:29pm UTC](https://discourse.pi-hole.net/t/audit-log/2058/20 "2025-05-13T21:29:14Z")

</div>

Add the domain to the _Exclusions_ in _ **Settings \> Web Interface / API** _:

 ![image](https://discourse-cdn.pi-hole.net/uploads/default/original/3X/c/1/c140a05c28217a6f7428c73300d66e8feb6bac88.png)

[Next page](https://discourse.pi-hole.net/t/audit-log/2058.md?page=2)
