{"timestamp":"2010-08-21T04:10:40.058649+0200","flow_id":2169942931720074,"pcap_cnt":11,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":6,"pkts_toclient":5,"bytes_toserver":666,"bytes_toclient":734,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:40.058649+0200","flow_id":2169942931720074,"pcap_cnt":11,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":6,"pkts_toclient":5,"bytes_toserver":666,"bytes_toclient":734,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:40.060328+0200","flow_id":2169942931720074,"pcap_cnt":23,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":12,"pkts_toclient":11,"bytes_toserver":1505,"bytes_toclient":1558,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:40.060328+0200","flow_id":2169942931720074,"pcap_cnt":23,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":12,"pkts_toclient":11,"bytes_toserver":1505,"bytes_toclient":1558,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:40.060775+0200","flow_id":2169942931720074,"pcap_cnt":25,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":13,"pkts_toclient":12,"bytes_toserver":1828,"bytes_toclient":2650,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:40.060775+0200","flow_id":2169942931720074,"pcap_cnt":25,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":13,"pkts_toclient":12,"bytes_toserver":1828,"bytes_toclient":2650,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:40.061020+0200","flow_id":2169942931720074,"pcap_cnt":27,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":14,"pkts_toclient":13,"bytes_toserver":2151,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:40.061020+0200","flow_id":2169942931720074,"pcap_cnt":27,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":14,"pkts_toclient":13,"bytes_toserver":2151,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:41.062684+0200","flow_id":2169942931720074,"pcap_cnt":28,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":15,"pkts_toclient":13,"bytes_toserver":2474,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:41.062684+0200","flow_id":2169942931720074,"pcap_cnt":28,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":15,"pkts_toclient":13,"bytes_toserver":2474,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:42.064975+0200","flow_id":2169942931720074,"pcap_cnt":29,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":16,"pkts_toclient":13,"bytes_toserver":2797,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:42.064975+0200","flow_id":2169942931720074,"pcap_cnt":29,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":16,"pkts_toclient":13,"bytes_toserver":2797,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:43.066440+0200","flow_id":2169942931720074,"pcap_cnt":30,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":17,"pkts_toclient":13,"bytes_toserver":3120,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:43.066440+0200","flow_id":2169942931720074,"pcap_cnt":30,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":17,"pkts_toclient":13,"bytes_toserver":3120,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:44.069406+0200","flow_id":2169942931720074,"pcap_cnt":31,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":18,"pkts_toclient":13,"bytes_toserver":3443,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:44.069406+0200","flow_id":2169942931720074,"pcap_cnt":31,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":18,"pkts_toclient":13,"bytes_toserver":3443,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:45.071860+0200","flow_id":2169942931720074,"pcap_cnt":34,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":19,"pkts_toclient":13,"bytes_toserver":3766,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:45.071860+0200","flow_id":2169942931720074,"pcap_cnt":34,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":19,"pkts_toclient":13,"bytes_toserver":3766,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:46.074582+0200","flow_id":2169942931720074,"pcap_cnt":35,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":20,"pkts_toclient":13,"bytes_toserver":4089,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:46.074582+0200","flow_id":2169942931720074,"pcap_cnt":35,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":20,"pkts_toclient":13,"bytes_toserver":4089,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:47.077373+0200","flow_id":2169942931720074,"pcap_cnt":36,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":21,"pkts_toclient":13,"bytes_toserver":4412,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:47.077373+0200","flow_id":2169942931720074,"pcap_cnt":36,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":21,"pkts_toclient":13,"bytes_toserver":4412,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:48.079264+0200","flow_id":2169942931720074,"pcap_cnt":37,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":22,"pkts_toclient":13,"bytes_toserver":4735,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:48.079264+0200","flow_id":2169942931720074,"pcap_cnt":37,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":22,"pkts_toclient":13,"bytes_toserver":4735,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:49.081172+0200","flow_id":2169942931720074,"pcap_cnt":38,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":23,"pkts_toclient":13,"bytes_toserver":5058,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:49.081172+0200","flow_id":2169942931720074,"pcap_cnt":38,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":23,"pkts_toclient":13,"bytes_toserver":5058,"bytes_toclient":4126,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:49.081621+0200","flow_id":2169942931720074,"pcap_cnt":40,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":24,"pkts_toclient":14,"bytes_toserver":5381,"bytes_toclient":5626,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:49.081621+0200","flow_id":2169942931720074,"pcap_cnt":40,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":24,"pkts_toclient":14,"bytes_toserver":5381,"bytes_toclient":5626,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.046975+0200","flow_id":2169942931720074,"pcap_cnt":47,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":27,"pkts_toclient":16,"bytes_toserver":5728,"bytes_toclient":7232,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.046975+0200","flow_id":2169942931720074,"pcap_cnt":47,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":27,"pkts_toclient":16,"bytes_toserver":5728,"bytes_toclient":7232,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.047832+0200","flow_id":2169942931720074,"pcap_cnt":49,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":28,"pkts_toclient":17,"bytes_toserver":5888,"bytes_toclient":7397,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.047832+0200","flow_id":2169942931720074,"pcap_cnt":49,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":28,"pkts_toclient":17,"bytes_toserver":5888,"bytes_toclient":7397,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.069314+0200","flow_id":2169942931720074,"pcap_cnt":51,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":29,"pkts_toclient":18,"bytes_toserver":6211,"bytes_toclient":7566,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.069314+0200","flow_id":2169942931720074,"pcap_cnt":51,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":29,"pkts_toclient":18,"bytes_toserver":6211,"bytes_toclient":7566,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.070276+0200","flow_id":2169942931720074,"pcap_cnt":53,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":30,"pkts_toclient":19,"bytes_toserver":6534,"bytes_toclient":7729,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.070276+0200","flow_id":2169942931720074,"pcap_cnt":53,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":30,"pkts_toclient":19,"bytes_toserver":6534,"bytes_toclient":7729,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.071524+0200","flow_id":2169942931720074,"pcap_cnt":55,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":31,"pkts_toclient":20,"bytes_toserver":6775,"bytes_toclient":8055,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.071524+0200","flow_id":2169942931720074,"pcap_cnt":55,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":31,"pkts_toclient":20,"bytes_toserver":6775,"bytes_toclient":8055,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.074402+0200","flow_id":2169942931720074,"pcap_cnt":57,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":32,"pkts_toclient":21,"bytes_toserver":7098,"bytes_toclient":8444,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.074402+0200","flow_id":2169942931720074,"pcap_cnt":57,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":32,"pkts_toclient":21,"bytes_toserver":7098,"bytes_toclient":8444,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.075431+0200","flow_id":2169942931720074,"pcap_cnt":59,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":33,"pkts_toclient":22,"bytes_toserver":7325,"bytes_toclient":8688,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.075431+0200","flow_id":2169942931720074,"pcap_cnt":59,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":33,"pkts_toclient":22,"bytes_toserver":7325,"bytes_toclient":8688,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.077766+0200","flow_id":2169942931720074,"pcap_cnt":61,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":34,"pkts_toclient":23,"bytes_toserver":7648,"bytes_toclient":9078,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.077766+0200","flow_id":2169942931720074,"pcap_cnt":61,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":34,"pkts_toclient":23,"bytes_toserver":7648,"bytes_toclient":9078,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.079163+0200","flow_id":2169942931720074,"pcap_cnt":63,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":35,"pkts_toclient":24,"bytes_toserver":7971,"bytes_toclient":9308,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.079163+0200","flow_id":2169942931720074,"pcap_cnt":63,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":35,"pkts_toclient":24,"bytes_toserver":7971,"bytes_toclient":9308,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.079962+0200","flow_id":2169942931720074,"pcap_cnt":65,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":36,"pkts_toclient":25,"bytes_toserver":8184,"bytes_toclient":9634,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.079962+0200","flow_id":2169942931720074,"pcap_cnt":65,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":36,"pkts_toclient":25,"bytes_toserver":8184,"bytes_toclient":9634,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.080617+0200","flow_id":2169942931720074,"pcap_cnt":67,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":37,"pkts_toclient":26,"bytes_toserver":8462,"bytes_toclient":10024,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.080617+0200","flow_id":2169942931720074,"pcap_cnt":67,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":37,"pkts_toclient":26,"bytes_toserver":8462,"bytes_toclient":10024,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.084755+0200","flow_id":2169942931720074,"pcap_cnt":71,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":39,"pkts_toclient":28,"bytes_toserver":8714,"bytes_toclient":10775,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.084755+0200","flow_id":2169942931720074,"pcap_cnt":71,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":39,"pkts_toclient":28,"bytes_toserver":8714,"bytes_toclient":10775,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.098682+0200","flow_id":2169942931720074,"pcap_cnt":76,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":41,"pkts_toclient":31,"bytes_toserver":8966,"bytes_toclient":11939,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.098682+0200","flow_id":2169942931720074,"pcap_cnt":76,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":41,"pkts_toclient":31,"bytes_toserver":8966,"bytes_toclient":11939,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.107361+0200","flow_id":2169942931720074,"pcap_cnt":77,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":42,"pkts_toclient":31,"bytes_toserver":9128,"bytes_toclient":11939,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.107361+0200","flow_id":2169942931720074,"pcap_cnt":77,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":42,"pkts_toclient":31,"bytes_toserver":9128,"bytes_toclient":11939,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.114207+0200","flow_id":2169942931720074,"pcap_cnt":80,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":43,"pkts_toclient":33,"bytes_toserver":9290,"bytes_toclient":12334,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.114207+0200","flow_id":2169942931720074,"pcap_cnt":80,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":43,"pkts_toclient":33,"bytes_toserver":9290,"bytes_toclient":12334,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.120781+0200","flow_id":2169942931720074,"pcap_cnt":81,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":44,"pkts_toclient":33,"bytes_toserver":9452,"bytes_toclient":12334,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.120781+0200","flow_id":2169942931720074,"pcap_cnt":81,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":44,"pkts_toclient":33,"bytes_toserver":9452,"bytes_toclient":12334,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.153362+0200","flow_id":2169942931720074,"pcap_cnt":86,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":46,"pkts_toclient":36,"bytes_toserver":9749,"bytes_toclient":12887,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.153362+0200","flow_id":2169942931720074,"pcap_cnt":86,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":46,"pkts_toclient":36,"bytes_toserver":9749,"bytes_toclient":12887,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.154342+0200","flow_id":2169942931720074,"pcap_cnt":88,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":47,"pkts_toclient":37,"bytes_toserver":9911,"bytes_toclient":13190,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.154342+0200","flow_id":2169942931720074,"pcap_cnt":88,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":47,"pkts_toclient":37,"bytes_toserver":9911,"bytes_toclient":13190,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.173935+0200","flow_id":2169942931720074,"pcap_cnt":90,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":48,"pkts_toclient":38,"bytes_toserver":10115,"bytes_toclient":13355,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.173935+0200","flow_id":2169942931720074,"pcap_cnt":90,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":48,"pkts_toclient":38,"bytes_toserver":10115,"bytes_toclient":13355,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.174344+0200","flow_id":2169942931720074,"pcap_cnt":92,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":49,"pkts_toclient":39,"bytes_toserver":10277,"bytes_toclient":13627,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.174344+0200","flow_id":2169942931720074,"pcap_cnt":92,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":49,"pkts_toclient":39,"bytes_toserver":10277,"bytes_toclient":13627,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:53.193970+0200","flow_id":2169942931720074,"pcap_cnt":94,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":50,"pkts_toclient":40,"bytes_toserver":10440,"bytes_toclient":13792,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:53.193970+0200","flow_id":2169942931720074,"pcap_cnt":94,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":50,"pkts_toclient":40,"bytes_toserver":10440,"bytes_toclient":13792,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:10:56.498343+0200","flow_id":2169942931720074,"pcap_cnt":427,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":217,"pkts_toclient":206,"bytes_toserver":25542,"bytes_toclient":43278,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:10:56.498343+0200","flow_id":2169942931720074,"pcap_cnt":427,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":217,"pkts_toclient":206,"bytes_toserver":25542,"bytes_toclient":43278,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:11:00.489860+0200","flow_id":2169942931720074,"pcap_cnt":431,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":219,"pkts_toclient":208,"bytes_toserver":25794,"bytes_toclient":43536,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:11:00.489860+0200","flow_id":2169942931720074,"pcap_cnt":431,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":219,"pkts_toclient":208,"bytes_toserver":25794,"bytes_toclient":43536,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}
{"timestamp":"2010-08-21T04:11:00.493077+0200","flow_id":2169942931720074,"pcap_cnt":433,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","alert":{"action":"allowed","gid":1,"signature_id":2029994,"rev":1,"signature":"ET HUNTING Suspicious NULL DNS Request","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Informational"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}},"app_proto":"dns","flow":{"pkts_toserver":220,"pkts_toclient":209,"bytes_toserver":25956,"bytes_toclient":43693,"start":"2010-08-21T04:10:40.051082+0200"}}
{"timestamp":"2010-08-21T04:11:00.493077+0200","flow_id":2169942931720074,"pcap_cnt":433,"event_type":"alert","src_ip":"10.0.2.30","src_port":44639,"dest_ip":"10.0.2.20","dest_port":53,"proto":"UDP","app_proto":"dns","flow":{"pkts_toserver":220,"pkts_toclient":209,"bytes_toserver":25956,"bytes_toclient":43693,"start":"2010-08-21T04:10:40.051082+0200"},"alert":{"action":"allowed","gid":1,"signature_id":2029995,"rev":1,"signature":"ET MALWARE Suspicious Long NULL DNS Request - Possible DNS Tunneling","category":"Unknown Classtype","severity":3,"metadata":{"updated_at":["2020_04_22"],"created_at":["2020_04_22"],"signature_severity":["Major"],"deployment":["Perimeter"],"attack_target":["DNS_Server"],"affected_product":["Windows_XP_Vista_7_8_10_Server_32_64_Bit"]}}}