Been a user for quite a while, just updated to the latest, thanks for a great package!
I have noticed a slight oddity that I thought I'd mention, along with a question, that go with the DNS Query Report feature...
The question is on sorting of the top 10 listing. I wanted to be sure I'm right in that it reads in 3 columns, first being the total number of DNS requests of any kind (?) by client, then the most requested unblocked domains by domain, then the most requested blocked ones?
On to the odd thing. I was looking over things after moving to 3.8.4 yesterday, and adding one of andryou's lists to my collection... I noticed yet again how chatty my Roku box is, but there was something wierd.
Here's the report output in part:
Top 10 Reporting
Count Name / IP-Address Count Domain Count Blocked Domain
1800 192.168.1.213 786 api-global.netflix.com 1128 cooper.logs.roku.com
1581 fde5:45cb:2b15::53f:4017:6ab2:90cf 599 www.google.com 208 scribe.logs.roku.com
830 LGwebOSTV.lan 177 spectrum.s3.amazonaws.com 118 ichnaea.netflix.com
668 amazon-7e76b5894.lan 176 push.prod.netflix.com 107 mobile-collector.newrelic.com
Filter the DNS Query result set for a particular domain, client or time frame.
cooper.logs.roku.com
Latest DNS Queries
Date Time Client Domain Answer Action
2019-10-06 15:21:57 192.168.1.213 cooper.logs.roku.com OK
2019-10-06 15:21:27 192.168.1.213 cooper.logs.roku.com NX
2019-10-06 15:20:57 192.168.1.213 cooper.logs.roku.com NX
2019-10-06 15:20:27 192.168.1.213 cooper.logs.roku.com NX
2019-10-06 15:19:56 192.168.1.213 cooper.logs.roku.com NX
2019-10-06 15:19:26 192.168.1.213 cooper.logs.roku.com NX
2019-10-06 15:19:05 192.168.1.213 cooper.logs.roku.com NX
Apologies for not figuring out how to get the indenting fixed for the top of the table.
Basic thing is, I noticed that the cooper.logs.roku.com entry was at the top of the blocked domains, but in the list of most recent I noticed it as a non blacklisted item. And, a little farther down the list, there it was blocked.
Doing the filtered search shows a long list of blocked instances, with the most recent instance not blocked. Hmmm... Far as I can tell, there wasn't a reload to refresh the lists. I have a twice a day cron entry for that, but its hours off till the next one, so I don't know what happened there?
Any good explanation why this would happen?