Also I had a look at pihole this morning, it must be the way I've got it setup but it doesn't show individual clients, it just lumps everything into my router IP address of 192.168.2.10 so it doesn't give any clues
What I do is: go to "query log" under "long term data", click on "date and time range", then "today". Under "recent queries", specify all (instead of last 10).
You should see a huge list of blocked and unblocked queries.
Then scroll down to some time of interest -- when you're fast asleep for example, and your main machines are off.
In my case I see masses of lookups related to microsoft, google, bitdefender, etc etc ... and peculiar stuff I've difficulty in explaining.
(Most of this emanated from my wife's windows laptop, which is supposedly asleep.)
I find all this enlightening, and slightly horrifying. Now and then I see something that definitely needs to be blocked.
Or some poll interval (for ntp or whatever) that can safely be whacked up.
(I'm sorry, I've not really mastered the chops to post screen shots very reliably.)