Last night, I bridged over the comcast router and Pi-Hole was working fine as the DNS for awhile, until it started saying "Lost Connection to API" this morning on the Pi-hole Admin Console. Tried to find some answers and tried a few things but I'm stuck - can't even get a proper debug token - help!
This is an abnormally large file. Something must have caused a very high number of queries today to make the log that large. Since there is a lot of data in that file, there should also be at least that much data in the long term database, and that is likely what is causing a problem with Pi-Hole working properly. The long term database is read each time Pi-Hole starts, to get the last 24 hours of data to populate the dashboard.
What is the output of these commands from the Pi terminal:
ls -lh /etc/pihole/pihole-FTL.db
echo ">stats" | nc localhost 4711
Note that this is not your debug log - it is the file where dnsmasq stores all the queries and replies for the day.
pi@raspberrypi:~ $ head -n25 /var/log/pihole.log
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:17 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 8 00:00:17 dnsmasq[4896]: forwarded local to 149.112.112.112
pi@raspberrypi:~ $
pi@raspberrypi:~ $ tail -n25 /var/log/pihole.log.1
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[A] www.msftncsi.com from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded www.msftncsi.com to 9.9.9.9
Oct 7 23:59:56 dnsmasq[4896]: query[SOA] local from 192.168.86.22
Oct 7 23:59:56 dnsmasq[4896]: forwarded local to 149.112.112.112
Oct 7 23:59:56 dnsmasq[4896]: forwarded local to 9.9.9.9
Oct 8 00:00:01 dnsmasq[4896]: query[SOA] local from 192.168.86.22
pi@raspberrypi:~ $
This seems to be a recurring request. I would look at that client. Each of these requests is being forwarded to both of your upstream servers, but since local is not a valid Internet address, it's just generating log entries.
I think I found the problem. After you said that the Pi hole was getting too much data, I realized that I may have manually added too many addresses to the 'blacklist' and 'regex'. So I formatted, reinstalled Raspbian and reinstalled Pi-hole without the manual additions. No problems. Thanks for your insight.