Reports → Query log (administrators; GET /api/v1/queries) lists
the queries of the journal, newest first, 100 at a time:
before (the id of the last row shown, for the next page), search
(part of the name, at most 253 characters; in the last 24 hours unless
from is given), status (all, allowed —
local answers included —, blocked, paused), device or person, and
from/to (milliseconds). Each row gives the time, the device and its
person, the name, the type (A, AAAA, HTTPS…), what Warda did and why
(lists, rules, categories, services, hours of Internet), the answer code and whether
it came from the cache. The devices of the adults who did not agree to
detailed reports are left out (a filter on one of them answers 403), and a
device given to a person shows only from that moment, as in the reports.
The page searches as one types (after half a second), follows the newest
queries every 5 seconds when Live is on, tints the blocked rows red and
those during a pause amber, and makes a name a rule for the whole network
in one click (Block or Allow, as on the page of the rules). The
filters are kept in the address of the page (#/queries?from=…&device=…).