PiHole query log not working

Please follow the below template, it will help us to help you!

Expected Behaviour:

query log on the pihole web interface shows all queries

Actual Behaviour:

no dns queries show although pihole is working correctly, tail pihole.log is also working

Debug Token:

https://tricorder.pi-hole.net/bOYoFVR6/

Please post a screen shot showing what you see in the query log. In this forum, you can paste an image directly into your reply.

is there anyone that can reply to this please? the problem still persists

Please post a new debug token, the logs expire after 48 hours.

https://tricorder.pi-hole.net/KY3zr5xt/

You have a number of database and shared memory errors.

   [2021-08-17 08:07:02.723 2344M] FATAL: Trying to access query ID -1, but maximum is 73728
   [2021-08-17 08:07:02.723 2344M]        found in FTL_query_in_progress() (/root/project/src/dnsmasq_interface.c:2181)
   [2021-08-17 08:07:02.724 2344M] Failed to unlock SHM lock: Operation not permitted
   [2021-08-17 08:11:27.995 2344M] FATAL: Trying to access query ID -1, but maximum is 73728
   [2021-08-17 08:11:27.997 2344M]        found in FTL_query_in_progress() (/root/project/src/dnsmasq_interface.c:2181)
   [2021-08-17 08:11:27.997 2344M] Failed to unlock SHM lock: Operation not permitted

Also it looks like there are some log file missing. Are you using any kind of changes to the /var/log directory?

i dont believe anything with that folder has changed

Can you show the output from

sudo ls -la /var/log/lighttpd/

total 456
drwxr-x--- 2 www-data www-data   4096 Aug 18 00:00 .
drwxr-xr-x 8 root     root       4096 Aug 18 00:00 ..
-rw-r--r-- 1 www-data www-data      0 Aug 18 00:00 access.log
-rw-r--r-- 1 www-data www-data  45591 Aug 17 19:25 access.log.1
-rw-r--r-- 1 www-data www-data    231 Jul 28 20:08 access.log.10.gz
-rw-r--r-- 1 www-data www-data     89 Jul 27 20:08 access.log.11.gz
-rw-r--r-- 1 www-data www-data     87 Jul 26 20:08 access.log.12.gz
-rw-r--r-- 1 www-data www-data   1700 Aug 12 12:18 access.log.2.gz
-rw-r--r-- 1 www-data www-data 295566 Aug  8 00:00 access.log.3.gz
-rw-r--r-- 1 www-data www-data  12864 Aug  3 23:21 access.log.4.gz
-rw-r--r-- 1 www-data www-data     90 Aug  2 20:08 access.log.5.gz
-rw-r--r-- 1 www-data www-data     90 Aug  1 20:08 access.log.6.gz
-rw-r--r-- 1 www-data www-data     90 Jul 31 20:08 access.log.7.gz
-rw-r--r-- 1 www-data www-data     88 Jul 30 20:08 access.log.8.gz
-rw-r--r-- 1 www-data www-data     88 Jul 29 20:08 access.log.9.gz
-rw-r--r-- 1 www-data www-data     74 Aug 18 00:00 error.log
-rw-r--r-- 1 www-data www-data     73 Aug 17 00:00 error.log.1
-rw-r--r-- 1 www-data www-data     88 Jul 30 00:00 error.log.10.gz
-rw-r--r-- 1 www-data www-data     88 Jul 29 00:00 error.log.11.gz
-rw-r--r-- 1 www-data www-data     88 Jul 28 00:00 error.log.12.gz
-rw-r--r-- 1 www-data www-data     89 Aug 16 00:00 error.log.2.gz
-rw-r--r-- 1 www-data www-data     88 Aug 15 00:00 error.log.3.gz
-rw-r--r-- 1 www-data www-data     86 Aug  8 00:00 error.log.4.gz
-rw-r--r-- 1 www-data www-data   1446 Aug  6 04:41 error.log.5.gz
-rw-r--r-- 1 www-data www-data    255 Aug  3 23:17 error.log.6.gz
-rw-r--r-- 1 www-data www-data     88 Aug  2 00:00 error.log.7.gz
-rw-r--r-- 1 www-data www-data     87 Aug  1 00:00 error.log.8.gz
-rw-r--r-- 1 www-data www-data     88 Jul 31 00:00 error.log.9.gz

Lets look at the errors:

sudo cat /var/log/lighttpd/error.log
sudo cat /var/log/lighttpd/error.log.1

2021-08-18 00:00:49: (server.c.1759) logfiles cycled UID = 0 PID = 22881
2021-08-17 00:00:04: (server.c.1759) logfiles cycled UID = 0 PID = 4051

Have you tried visiting the page in the last few days?

i just checked now, issue is still the same

And is there anything new in the error logs?

1 Like

no the logs are the same. Ive noticed that my linksys nodes are requesting a abnormal amount, could this be linked to the issue?

I don't know. I don't think so but thanks for mentioning it.

Can you open the page in your web browser and open the F12 developer panels to see if there are any errors being displayed?

queries.php:1 Refused to load the image 'data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB3aWR0aD0iNjAwIiBoZWlnaHQ9IjYwMCI+PGRlZnM+PGZpbHRlciBpZD0iZGFya3JlYWRlci1pbWFnZS1maWx0ZXIiPjxmZUNvbG9yTWF0cml4IHR5cGU9Im1hdHJpeCIgdmFsdWVzPSIwLjMzMyAtMC42NjcgLTAuNjY3IDAuMDAwIDEuMDAwIC0wLjY2NyAwLjMzMyAtMC42NjcgMC4wMDAgMS4wMDAgLTAuNjY3IC0wLjY2NyAwLjMzMyAwLjAwMCAxLjAwMCAwLjAwMCAwLjAwMCAwLjAwMCAxLjAwMCAwLjAwMCIgLz48L2ZpbHRlcj48L2RlZnM+PGltYWdlIHdpZHRoPSI2MDAiIGhlaWdodD0iNjAwI...lJU2hRU1lHS0RSZVR6UDBWbzlFSGthRFlNODVVVVRPWGs3QllFNmwwKzdKY2pIUkNveWpQOEF2RjUrUDZ3VmxDbFJ0Qk1aVFZCY0M4WG1kL3EvVzRNQldLSVZBL3dCWGJwMzFHMHlVRnZRTHpDV1k1VWdDZy84QWlicHZIVVdkb1RzWVV1NVorZW9LTlF3TU5TRlV6THNzelNSUU0wK0F3VFBKZk9nRHdlWUZrMUd5TmIvUXpnd1JvWmhtT2ZwYWNtQkJLM0RRRlpKT1Q4OWFKQWpHSGgzQVIrUDkvZkhrSlRGTVF2cUtySE9ack5rYW5xc0ovSUpWaXFGNDk5RUc2WUJRTkkxVThnYitCSnlLeFJDcC84UUFGQkVCQUFBQUFBQUFBQUFBQUFBQUFBQUF3UC9hQUFnQkFnRUJQd0F2ei8vRUFCUVJBUUFBQUFBQUFBQUFBQUFBQUFBQUFNRC8yZ0FJQVFNQkFUOEFMOC8vMlE9PSIgLz48L3N2Zz4=' because it violates the following Content Security Policy directive: "img-src 'self'".

What URL are you using to access the dashboard?

192.168.1.127/admin/queries.php

That decodes to something that contains darkreader-image-filter. Does that mean anything to you?